Hand with stack of money

An Example of Too Much Trust in IT

Hey, remember when I wrote about network security monitoring and whether you trust your IT folks?

Or the podcast discussion we had on the Nuix Unscripted podcast?

One of our big takeaways from the discussion was to make sure there are multiple people involved in deciding what to monitor, or who to target, to avoid a situation where one rouge security person is misusing the power. Yesterday, I saw a post by Sharon Nelson that laid out another obvious example of a situation where multiple people should have had eyes on something before paying the invoice:

He pleaded guilty to one count of wire fraud for having set up a shell company and billing his employer for firewalls and services that “Interactive Systems” never actually installed.

Turns out the IT Executive sent invoices for a wide variety of hardware and services, approved the invoices himself, and got the company to pay them, all without ever doing any work at all. To the tune of $6 million before anyone started to ask about the company that was billing them so much money.

So, yeah. Maybe more than one person needs to approve these invoices and verify that the stuff you’re paying for, actually exists. There’s simply no reason to trust anyone that much!

Similar Posts

  • Twitter Hackers Were Smart, But Hardly Genius

    Smart enough to get in, not smart enough to cover their tracks when getting paid. That doesn’t seem so smart. Which goes to show, that security around Twitter could have been a lot better, and people who work there maybe should have been a little less careless. That doesn’t bode well for the rest of us when even a big tech company can’t get this right. How many of us have people on staff who might fall for this kind of phone-based attack?

    What should we think of the complicated, super-smart hackers who also manage to be so easily identifiable? Should we accept that the hardest thing about any conspiracy, and this goes for all the conspiracy theories out there, is making sure one person doesn’t do something stupid and give it all away? That. actually, is nearly impossible, and is the one thing that makes most theories unbelievable to me. This hack proves to be a perfect example.

  • Monday morning

    Gee and there are 1171 unread items in my aggregator, so here’s my attempt at noting things to look at later: The IE Team has a blog! RSS Traffic burdens publisher’s servers. -Not a big surprise, but definitely reason to turn off the aggregator every now and then. I generally only poll sites 2-3 times…

  • |

    Linked: Law Firm Data Security Vulnerabilities

    These results from the 2018 ABA Legal Technology Survey are not at all good, given how much information is laying around law firms these days. “Less than half of the responding firms have the following policies or plans that are important facets of a law firm’s security posture:  computer acceptable use policy (41%); remote access…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)